This is an English translation provided for convenience. The German version at https://boothdock.eu/datenschutz/ is the legally authoritative version; in case of any discrepancy, the German text applies.
Last updated: June 16, 2026. This privacy notice describes BoothDock's target architecture. Product features that are not yet active are described as target architecture and will be reviewed again before activation.
1. Controller
Daniel Rau
trading as BoothDock
Sole proprietorship, side business (Einzelunternehmen im Nebenerwerb)
Small business scheme under § 19 UStG (German VAT Act)
Herrweg 7
52511 Geilenkirchen
Germany
Contact for privacy inquiries: daniel@photobox-heinsberg.de
Phone: +49 2451 9017128
No data protection officer has currently been appointed. Privacy inquiries can be sent directly to the contact address above.
2. Scope and roles
This privacy notice applies to the website at boothdock.eu, to demo and support contacts, and to the planned BoothDock product architecture comprising BoothDock Studio, BoothDock Hub at https://boothdock.cloud and BoothDock Gallery.
For the website, demo requests, operator accounts, license management, support and billing, BoothDock acts as the data controller. For event, customer, guest and media data that photo booth operators have processed in the Hub, in Studio or in Gallery, BoothDock generally acts as a data processor. The respective photo booth operator remains the controller towards guests, event customers and other data subjects. A data processing agreement (DPA) under Art. 28 GDPR is intended to be put in place with operators for this purpose.
For this processor relationship, a data processing agreement, an overview of the sub-processors used, and technical and organizational measures are planned before productive use.
3. Principles of processing
BoothDock is being built around the principles of purpose limitation, data minimization, access restriction, storage limitation and confidentiality. Private gallery links, role-based permissions, deletion periods and traceable upload/sync status are part of the target architecture.
Photos and videos may contain personal data and, in individual cases, may reveal special categories of personal data. BoothDock does not analyze such characteristics automatically, does not perform facial recognition and does not create guest profiling.
If operators process event media from which special categories of personal data under Art. 9 GDPR may be inferred, operators must assess the appropriate legal basis, provide notice at the event, and establish their own consent and deletion processes. BoothDock provides the technical platform for this purpose and does not evaluate such characteristics.
4. Website and server logs
When the website is accessed, technically necessary connection data is processed. This can include IP address, date and time of access, requested file, HTTP status, amount of data transferred, referrer, and browser and operating system information.
The purpose is secure operation, error analysis and protection against misuse. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest is the stable and secure operation of the website. The website is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany.
The marketing website currently does not use external tracking scripts, marketing cookies, or an embedded contact form.
5. Cookies and local storage
The marketing website currently does not set any non-essential cookies. Should analytics, marketing or third-party cookies be introduced later, this will only happen after obtaining prior consent, where such consent is required.
In the BoothDock Hub and in private galleries, technically necessary cookies or comparable storage technologies may be used, for example for login sessions, security functions, CSRF protection, language settings, or to provide a service explicitly requested by the user. The legal bases are Art. 6(1)(b) or (f) GDPR and, where applicable, § 25(2) TDDDG (German Telecommunications-Digital-Services-Data-Protection Act).
6. Demo requests, email and support
When contacted by email or via a demo request, the information submitted is processed. This can include name, company, website, phone number, email address, number of photo booths, typical events, technical questions and message content.
The purposes are handling the inquiry, demo preparation, communication, quotation and pre-contractual measures. The legal bases are Art. 6(1)(b) GDPR for pre-contractual or contractual inquiries and Art. 6(1)(f) GDPR for general communication and following up on legitimate inquiries.
Contact inquiries are deleted once they are no longer required for processing, unless statutory retention obligations, contract documentation or legitimate interests require further retention.
Demo requests can also be sent to contact@deadlineworks.com.
7. Operator accounts and BoothDock Hub
In the BoothDock Hub, account, contract and usage data will likely be processed for operators and team members. This can include name, email address, company, role/permissions, login data, security events, license status, booked packages, settings, customer and event data, and technical log data.
The purposes are providing the Hub, authentication, role and permission management, event preparation, synchronization, support, operational security, license management and billing. The legal bases are Art. 6(1)(b) GDPR for contract performance, Art. 6(1)(c) GDPR for legal obligations, and Art. 6(1)(f) GDPR for security, misuse detection and product operation.
8. BoothDock Studio at the event PC
BoothDock Studio is designed as a desktop app for the event PC. There, photos, videos, session data, print data, gallery index, upload queues, camera/printer status, error messages and sync status can be processed locally.
Where Studio synchronizes data with the Hub, this occurs to perform the operator agreement and, for event and media data, on behalf of the respective operator. The operator remains responsible for ensuring an appropriate legal basis and transparent information towards data subjects for photos, event data and guest information.
9. BoothDock Gallery and private QR galleries
BoothDock Gallery provides private gallery links for customers and guests. This can involve processing photos, videos, thumbnails, file names, timestamps, event name, gallery code, download/release status, technical access data, IP address, browser information, and, where an operator enables such features, optional details voluntarily provided such as name or email address.
Galleries are designed as private links rather than publicly indexed collection pages. The legal basis for providing them to guests is generally determined by the respective operator. BoothDock generally processes this data as a data processor.
10. Billing, taxes and accounting
When BoothDock is used on a paid basis, invoicing, payment and contract data can be processed. This can include name, address, company, email address, scope of services, invoice numbers, payment status and tax-relevant information.
The legal bases are Art. 6(1)(b) GDPR for contract performance and Art. 6(1)(c) GDPR for statutory retention and documentation obligations.
11. Recipients and service providers
Personal data is only shared where necessary for operation, contract performance, support, security, billing or statutory obligations.
- IONOS SE for hosting, domains, SSL, email and infrastructure services.
- GitHub for source code management and deployment processes; productive event and media data is not intended to be stored there.
- Optional payment, support, monitoring or email service providers introduced later, where necessary for operation.
- Authorities, tax advisors or legal counsel, where legally required or necessary to enforce legal claims.
12. Transfers to third countries
BoothDock is designed for EU-/Germany-centric processing. Under the target architecture, event and media data is not intended to be deliberately transferred to third countries outside the EU/EEA.
Where individual service providers process data outside the EU/EEA, or access from third countries cannot be excluded, this only occurs on the basis of appropriate safeguards, for example an adequacy decision, EU Standard Contractual Clauses, or comparable data protection mechanisms.
13. Retention periods and deletion concept
Data is only retained for as long as necessary for the respective purpose or as required by statutory obligations.
- Website server logs: only for operation, security and error analysis; specific periods depend on the hosting setup.
- Contact and demo inquiries: until final processing, and afterwards as needed for follow-up questions or documentation obligations.
- Operator accounts and contract data: for the duration of the contract and afterwards according to statutory retention periods.
- Invoicing and accounting data: in accordance with statutory retention obligations.
- Event and media data: according to operator configuration; the aim is a clear expiry and deletion period per event/gallery.
- Backups: time-limited and not intended as a permanent archive for deleted event data.
14. Security and technical measures
BoothDock is operated with technical and organizational measures appropriate to the respective risk. In the target architecture, these include in particular TLS encryption, role-based access, private gallery links, separated operator areas, logging of security-relevant events, access restrictions for support, backups, deletion processes, and data-minimized logging.
Access to event or media data by BoothDock only occurs where necessary for operation, support, security, or upon the operator's instruction.
15. Automated decision-making
BoothDock does not make automated decisions within the meaning of Art. 22 GDPR and does not create profiling of guests, customers or operators.
16. Data subject rights
Data subjects have rights under the GDPR to access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on consent, that consent can be withdrawn at any time with effect for the future.
Requests can be sent to daniel@photobox-heinsberg.de. For event, guest or media data belonging to an operator, it may be necessary to forward the request to, or coordinate it with, the respective operator, since the operator is the controller for that processing.
17. Right to lodge a complaint
Data subjects have the right to lodge a complaint with a data protection supervisory authority. For the controller's location, the competent authority is the Landesbeauftragte fuer Datenschutz und Informationsfreiheit Nordrhein-Westfalen (State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia): https://www.ldi.nrw.de/.
18. Changes to this privacy notice
This privacy notice will be updated whenever features, service providers used, domains, retention periods or legal bases change. The current version is available at https://boothdock.eu/en/privacy/.